patches - News, Features, and Slideshows

News

  • Apache Struts security update fixes critical vulnerabilities

    The Apache Software Foundation has released Struts 2.3.15.1, a security update for its popular Java Web application development framework that addresses two vulnerabilities, including a critical one that could allow remote attackers to execute arbitrary code on the server.

    Written by Lucian Constantin17 July 13 11:56
  • Patch Tuesday: Malicious fonts bedevil Microsoft Windows

    Of the six critical security bulletins Microsoft issued in its Patch Tuesday monthly release of software updates, three address a vulnerability in how Microsoft software renders fonts.

    Written by Joab Jackson09 July 13 19:35
  • Critical vulnerabilities found in single sign-on enterprise tool Atlassian Crowd

    A critical vulnerability that could allow remote attackers to access sensitive enterprise log-in credentials and other data was fixed last week in Crowd, a single sign-on (SSO) and identity management tool used by large organizations to simplify access to their internal Web applications and services.

    Written by Lucian Constantin01 July 13 16:13
  • Vulnerabilities found in code library used by encrypted phone call apps

    ZRTPCPP, an open-source library that's used by several applications offering end-to-end encrypted phone calls, contained three vulnerabilities that could have enabled arbitrary code execution and denial-of-service attacks, according to researchers from security firm Azimuth Security.

    Written by Lucian Constantin01 July 13 12:00
  • Many companies are negligent about SAP security, researchers say

    SAP has significantly improved the security of its products over the past few years but many of its customers are negligent with their deployments, which exposes them to potential attacks that could cripple their businesses, according to security researchers.

    Written by Lucian Constantin19 June 13 18:31
  • Microsoft launches security bounty programs for Windows 8.1 and IE 11 Preview

    Microsoft will pay security researchers for finding and reporting vulnerabilities in the preview version of its Internet Explorer 11 (IE 11) browser, for finding novel techniques to bypass exploit mitigations present in Windows 8.1 or later versions and for coming up with new ideas to defend against exploits.

    Written by Lucian Constantin19 June 13 17:03
  • Microsoft patches critical IE vulnerabilities and actively exploited Office flaw

    A new batch of security updates released by Microsoft on Tuesday address a total of 23 vulnerabilities in Internet Explorer, Windows and Microsoft Office, including one that is actively exploited by attackers. The handling of digital certificates in Windows was also improved.

    Written by Lucian Constantin11 June 13 22:23
  • ISC patches publicly disclosed denial-of-service vulnerability affecting BIND 9

    The Internet Systems Consortium (ISC), the organization that develops and maintains the widely used BIND DNS (Domain Name System) software, has patched a publicly disclosed vulnerability that can be used to remotely crash DNS servers running recent releases of BIND 9.

    Written by Lucian Constantin06 June 13 11:50
  • Oracle reveals plans for Java security improvements

    Oracle plans to make changes to strengthen the security of Java, including fixing its certificate revocation checking feature, preventing unsigned applets from being executed by default and adding centralized management options with whitelisting capabilities for enterprise environments.

    Written by Lucian Constantin31 May 13 13:26
[]